← Vulnerability feed

Vulnerability record · CVE-2008-4696 · published 23 October 2008

CVE-2008-4696: Opera stored XSS via unescaped anchor identifier in History Search

Opera · Opera

Opera before 9.61 fails to escape the anchor identifier (the optional fragment) before storing it in the History Search database (md.dat). A remote attacker can inject arbitrary web script or HTML that is later rendered from stored history data. This is a stored cross-site scripting flaw in the browser itself, affecting all users of the vulnerable version.

4.3 CVSS 2.0 Medium EPSS 46% · top 1.2% CWE-79 · Cross-site scripting
4.3CVSS 2.0 base score
46%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
40References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Cross-site scripting (XSS) vulnerability in Opera.dll in Opera before 9.61 allows remote attackers to inject arbitrary web script or HTML via the anchor identifier (aka the "optional fragment"), which is not properly escaped before storage in the History Search database (aka md.dat).

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

medium priorityCVSS 2.0 score is 4.3 (MEDIUM) with only partial integrity impact, but public exploit code and high EPSS percentile raise the practical risk.

What it is

Opera before 9.61 fails to escape the anchor identifier (the optional fragment) before storing it in the History Search database (md.dat). A remote attacker can inject arbitrary web script or HTML that is later rendered from stored history data. This is a stored cross-site scripting flaw in the browser itself, affecting all users of the vulnerable version.

Impact

An attacker can execute arbitrary script or HTML in the context of the victim's browser session, potentially stealing data or performing actions as the user. The CVSS vector shows partial integrity impact only, with no confidentiality or availability impact.

Attack surface

Reached remotely over the network (AV:N) with medium complexity (AC:M) and no authentication required (Au:N). The description does not state whether user interaction is needed, but the vector and stored nature imply the victim must visit a crafted page or link for the payload to be stored and later rendered.

Exploitation

Not listed in CISA KEV. EPSS 30-day probability is 0.45729 (98.7th percentile), indicating high predicted activity. Reference tags include Exploit and Patch, and an Exploit-DB entry exists, so public exploit code is available.

What to do

  • Upgrade Opera to version 9.61 or later, which contains the fix.
  • Apply vendor patches from the Opera 9.61 changelogs for all affected platforms.
  • If upgrade is not possible, restrict use of the vulnerable Opera version for untrusted web browsing.
  • Clear or disable the History Search database (md.dat) where feasible to remove stored payloads.

Detection

  • Monitor for Opera versions below 9.61 in asset inventories and flag them for upgrade.
  • Inspect md.dat or History Search data for unexpected script or HTML content in anchor identifiers.
  • Review web proxy or browser logs for requests containing suspicious fragment identifiers targeting Opera users.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00009.html
http://secunia.com/advisories/32299 Vendor Advisory
http://secunia.com/advisories/32394
http://secunia.com/advisories/32538
http://security.gentoo.org/glsa/glsa-200811-01.xml
http://securityreason.com/securityalert/4504
http://www.openwall.com/lists/oss-security/2008/10/21/6
http://www.openwall.com/lists/oss-security/2008/10/22/5
http://www.opera.com/docs/changelogs/freebsd/961/ Patch
http://www.opera.com/docs/changelogs/linux/961/ Patch
http://www.opera.com/docs/changelogs/mac/961/ Patch
http://www.opera.com/docs/changelogs/solaris/961/
http://www.opera.com/docs/changelogs/windows/961/
http://www.opera.com/support/search/view/903/ Vendor Advisory
http://www.security-assessment.com/files/advisories/2008-10-22_Opera_Stored_Cross_Site_Scripting.pdf
http://www.securityfocus.com/archive/1/497646/100/0/threaded
http://www.securityfocus.com/bid/31869 ExploitPatch
http://www.vupen.com/english/advisories/2008/2873
https://exchange.xforce.ibmcloud.com/vulnerabilities/46003
https://www.exploit-db.com/exploits/6801
http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00009.html
http://secunia.com/advisories/32299 Vendor Advisory
http://secunia.com/advisories/32394
http://secunia.com/advisories/32538
http://security.gentoo.org/glsa/glsa-200811-01.xml
http://securityreason.com/securityalert/4504
http://www.openwall.com/lists/oss-security/2008/10/21/6
http://www.openwall.com/lists/oss-security/2008/10/22/5
http://www.opera.com/docs/changelogs/freebsd/961/ Patch
http://www.opera.com/docs/changelogs/linux/961/ Patch
http://www.opera.com/docs/changelogs/mac/961/ Patch
http://www.opera.com/docs/changelogs/solaris/961/
http://www.opera.com/docs/changelogs/windows/961/
http://www.opera.com/support/search/view/903/ Vendor Advisory
http://www.security-assessment.com/files/advisories/2008-10-22_Opera_Stored_Cross_Site_Scripting.pdf
http://www.securityfocus.com/archive/1/497646/100/0/threaded
http://www.securityfocus.com/bid/31869 ExploitPatch
http://www.vupen.com/english/advisories/2008/2873
https://exchange.xforce.ibmcloud.com/vulnerabilities/46003
https://www.exploit-db.com/exploits/6801

Track CVE-2008-4696 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-4293Opera vulnerabilityUnspecified vulnerability in Opera before 9.52 on Windows, when registered as a protocol handler, allows remote attackers to cause a denial of servic…EPSS 4.5%10.0CVE-2008-3079Opera vulnerabilityUnspecified vulnerability in Opera before 9.51 on Windows allows attackers to execute arbitrary code via unknown vectors.EPSS 3.0%9.3CVE-2008-5679Opera vulnerabilityThe HTML parsing engine in Opera before 9.63 allows remote attackers to execute arbitrary code via crafted web pages that trigger an invalid pointer …EPSS 3.3%9.3CVE-2008-5178Opera memory buffer overflow vulnerabilityHeap-based buffer overflow in Opera 9.62 on Windows allows remote attackers to execute arbitrary code via a long file:// URI. NOTE: this might overla…EPSS 32%9.3CVE-2008-4794Opera improper input validation vulnerabilityOpera before 9.62 allows remote attackers to execute arbitrary commands via the History Search results page, a different vulnerability than CVE-2008-…EPSS 4.5%9.3CVE-2008-4695Opera information exposure vulnerabilityOpera before 9.60 allows remote attackers to obtain sensitive information and have unspecified other impact by predicting the cache pathname of a cac…EPSS 6.0%9.3CVE-2008-1761Opera vulnerabilityOpera before 9.27 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted newsfeed source, whi…EPSS 7.6%9.3CVE-2008-1764Opera vulnerabilityUnspecified vulnerability in Opera before 9.27 has unknown impact and attack vectors related to "keyboard handling of password inputs."EPSS 2.0%

Source: NIST National Vulnerability Database (record CVE-2008-4696), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.